creating/remembering secure passwords hain-lee hsueh michael duong

10
Creating/Remembering Secure Passwords Hain-Lee Hsueh Michael Duong

Upload: homer-stone

Post on 04-Jan-2016

233 views

Category:

Documents


0 download

TRANSCRIPT

Galactic Security Defender

Creating/Remembering Secure PasswordsHain-Lee HsuehMichael Duong

Secure And Memorable PasswordsProblem:Maintaining many random passwords is difficult to remember: BADMaintaining a single master password is extremely insecure: BADShort passwords utilizing common words: BAD

Secure And Memorable PasswordsPossible Elaboration StrategiesLeverage personal word associations within the password (chunking)Create a mental visual or story of the password that only makes sense to youEstablish an obscure but memorable connection between password and the thing being protectedExamplePW for an amazon account: samtoucanfruitgoodsA long time ago in a galaxy far, far awaySTARWARSSecuring the New Hope

Rebel spaceships, striking from a hidden base, have won their first victory against the evil Galactic Empire.

In anticipation of the empire striking back, the rebel forces decide to re-secure their galactic infrastructure to avoid enemy infiltration.

You have been tasked to manage security access to all of the rebel forces vital resources. This entails creating memorable yet secure passwords to guard against unauthorized breaches, and granting access to legitimate entities.

May the Schwartz be with you.Core MechanicYou are captain of the command center, from which you can oversee all of the rebel resources hovering in spaceE.g. weapon chambers, food reserves, infirmary ships, refueling stations, money vaults, docking stations, super laser control roomsInitially, all resources are unlocked; you need to create a distinct password to protect access to each resourceDuring game play, additional resources (e.g. new food reserves) may be introduced that need to be secured

Core MechanicGalactic Empire ships are trying to compromise rebel resources; you must lock each resource (by creating a secure password) before enemy ships reach themFailure to do so will result in a hostile takeover of the rebel forces, and captivity in carbonite

Core MechanicConcurrently, rebel ships periodically need legitimate access, which you grant them by providing the password upon each requestYou get three attempts per resource to enter the password before the resource is indefinitely lockedFailure to do so will result in exile to the distant planet of DANtooine*

*Real Star Wars planet: http://en.wikipedia.org/wiki/Dantooine#Dantooine

Star Wars Main ThemeTokyo Kosei Wind OrchestraStar Wars OST2000Blues195328.8